System and method for controlling the downstream preservation and destruction of electronic mail
Abstract
A system and method for controlling the downstream preservation and destruction of electronic mail by encrypting the electronic mail and limiting access to the encrypted file based on registration of recipient e-mail addresses, and detection and restriction of output functionality available to the recipient. The registration procedure limits access to recipients included on an access control list, who receive a pre-configured reader and then authenticate their e-mail address to the reader via a known SMTP Server. The sender of an e-mail is provided with a dialog for determining the limitations on access to the e-mail by the recipient: whether the e-mail is to be inaccessible after a certain period of time, whether a recipient may copy or print the e-mail and/or its attachments, or whether a password is required to read the e-mail. These limitations comprise an access control policy applicable to the e-mail, the pre-configured reader being adapted to decrypt the e-mail and apply the policy.
Claims
exact text as granted — not AI-modified1 . A system for controlling the downstream preservation and destruction of electronic mail, comprising:
means for encrypting a message, the message consisting of an electronic mail message, an access control list containing an electronic mail address of a recipient, and a policy limiting use of said electronic mail message by said recipient; and means for authenticating a reader for said recipient's electronic mail address, said authenticated reader being adapted to decrypt said message and apply said policy, wherein said authenticated reader extracts said access control list from said encrypted message and determines whether said recipient's electronic mail address is on said access control list.
2 . A system as is claim 1 , wherein a sender of said electronic mail message determines said policy through a dialog provided within an electronic mail client of said sender.
3 . A system as in claim 2 , wherein said policy dialog is provided by a plug-in to said sender's electronic mail client.
4 . A system as in claim 2 , wherein said policy dialog includes determining whether said reader of said recipient will allow printing of said electronic mail message.
5 . A system as in claim 4 , wherein said policy dialog includes means for determining whether said reader of said recipient will allow printing of attachments to said electronic mail message.
6 . A system as in claim 1 , wherein said means for authenticating further comprise:
means for providing said reader to said recipient, said reader having an address list, there being a predetermined unlock address marked as authenticated on said address list; means for sending from said reader an authentication request message to a predetermined address, said authentication request message containing said recipient's electronic mail address and a date time stamp; means for receiving from said predetermined address an authentication message addressed to said recipient, said authentication message having an access control list containing said predetermined unlock address, said recipient's electronic mail address and said date time stamp; and means for using said predetermined unlock address to decrypt said authentication message, and determining whether said recipient's electronic mail address and said date time stamp in said authentication message match the recipient's electronic mail address and date time stamp sent from said reader.
7 . A system as in claim 6 , wherein said reader is provided to said recipient in response to a request from said recipient's email client to said predetermined address.
8 . A system as in claim 6 , wherein said reader is pre-packaged in said recipient's email client.
9 . A system as in claim 7 , wherein said predetermined address is a location of a web server and said authentication request message is sent automatically by a simple mail transfer protocol (SMTP) client within said reader.
10 . A system as in claim 7 , wherein said predetermined address is a known electronic mail support address and said authentication request message is a text file encrypted by said reader and sent by said recipient's email client.
11 . A method for controlling the downstream preservation and destruction of electronic mail, comprising the steps of:
encrypting a message, the message consisting of an electronic mail message, an access control list containing an electronic mail address of a recipient, and a policy limiting use of said electronic mail message by said recipient; and authenticating a reader for said recipient's electronic mail address, said authenticated reader being adapted to decrypt said message and apply said policy, wherein said authenticated reader extracts said access control list from said encrypted message and determines whether said recipient's electronic mail address is on said access control list.
12 . A method as is claim 11 , wherein a sender of said electronic mail message determines said policy through a dialog provided within an electronic mail client of said sender.
13 . A method as in claim 12 , wherein said policy dialog is provided by a plug-in to said sender's electronic mail client.
14 . A method as in claim 12 , wherein said policy dialog includes determining whether said reader of said recipient will allow printing of said electronic mail message.
15 . A method as in claim 14 , wherein said policy dialog includes determining whether said reader of said recipient will allow printing of attachments to said electronic mail message.
16 . A method as in claim 11 , wherein said authentication step further comprises the steps of:
providing said reader to said recipient, said reader having an address list, there being a predetermined unlock address marked as authenticated on said address list; sending from said reader an authentication request message to a predetermined address, said authentication request message containing said recipient's electronic mail address and a date time stamp; receiving from said predetermined address an authentication message addressed to said recipient, said authentication message having an access control list containing said predetermined unlock address, said recipient's electronic mail address and said date time stamp; and using said predetermined unlock address to decrypt said authentication message, and determining whether said recipient's electronic mail address and said date time stamp in said authentication message match the recipient's electronic mail address and date time stamp sent from said reader.
17 . A method as in claim 16 , wherein said reader is provided to said recipient in response to a request from said recipient's email client to said predetermined address.
18 . A method as in claim 16 , wherein said reader is pre-packaged in said recipient's email client.
19 . A method as in claim 17 , wherein said predetermined address is a location of a web server and said authentication request message is sent automatically by a simple mail transfer protocol (SMTP) client within said reader.
20 . A method as in claim 17 , wherein said predetermined address is a known electronic mail support address and said authentication request message is a text file encrypted by said reader and sent by said recipient's email client.Join the waitlist — get patent alerts
Track US2005204008A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.